Less personal data to store
You receive the answer to your question, not a document full of details you never needed. What you do not hold cannot leak.
Collecting ID scans and certificates costs time, creates risk and annoys customers. With Bisotun you request specific items, such as "over 18" or "member of" from cards that organizations can issue, and receive them with a cryptographic proof that a trusted issuer vouches for them.
You receive the answer to your question, not a document full of details you never needed. What you do not hold cannot leak.
No staff comparing photos and stamps. The issuer's signature is checked automatically and you get a clear valid / not valid result.
A customer approves one request in their wallet instead of filling in forms and uploading files, and you can decide immediately.
Offer "Log in with Bisotun": no password database to protect, no reset emails, and no passwords for attackers to guess or reuse.
An altered or invented card fails the signature check, and a copied card is useless without the owner's wallet and PIN.
Customers see exactly what you ask for. Asking only for what you need builds trust.
| Collecting ID copies and certificates | Requesting Bisotun cards |
|---|---|
| Customer uploads a full document | Customer shares only the requested items |
| You store the file and must protect it | You store only what you decide to keep from the result |
| Staff check authenticity by eye, or contact the issuer | The issuer's signature is verified automatically in the session |
| Days of back-and-forth for unclear scans | An answer as soon as the customer approves |
| Separate usernames and passwords | Passwordless login with the customer's wallet |
The wallet's account ID: a random identifier, the same towards every service. Suitable for passwordless login to an account.
The verified email address, confirmed by Bisotun. The usual choice for login and sign-up once it is available.
Any card an organization issues on Bisotun: age, education, membership, employment and more. You can ask for single items, several items from several cards, alternatives ("student card or membership card"), optional items, or a specific value ("level: gold").
It lists the items you need and signs the request with your key. The browser never sees your key and cannot change what is asked.
A QR code on computers, an "Open Bisotun Wallet" button on phones, in Persian, Arabic or English.
Their wallet shows who is asking and which items, and they share or decline.
Bisotun's session server checks the issuer's signatures, the expiry dates and that the proof belongs to the customer's wallet.
The result, signed by the session server, is posted to your server. You check the status and the items, then log the customer in or continue your process.
Write to support@bisotun.app with what you want to verify and why.
You receive a requestor name, register your public key (or receive a shared secret), and get permission for exactly the items you need. Requests for anything else are refused.
Add the widget and two or three endpoints on your server. See the developer guide.
Use the demo, a sample service with passwordless login, to see the full flow from the customer's side.
Ready to replace document uploads?